Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:1851-1

Опубликовано: 22 окт. 2015
Источник: suse-cvrf

Описание

Security update for apache2

The Apache2 webserver was updated to fix several issues:

Security issues fixed:

  • The chunked transfer coding implementation in the Apache HTTP Server did not properly parse chunk headers, which allowed remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c. [bsc#938728, CVE-2015-3183]
  • The LOGJAM security issue was addressed by: [bnc#931723 CVE-2015-4000]
    • changing the SSLCipherSuite cipherstring to disable export cipher suites and deploy Ephemeral Elliptic-Curve Diffie-Hellman (ECDHE) ciphers.
    • Adjust 'gensslcert' script to generate a strong and unique Diffie Hellman Group and append it to the server certificate file.
  • The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x did not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allowed remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior. [bnc#938723 bnc#939516 CVE-2015-3185]
  • Tomcat mod_jk information leak due to incorrect JkMount/JkUnmount directives processing [bnc#927845 CVE-2014-8111]

Other bugs fixed:

  • Now provides a suse_maintenance_mmn_# [bnc#915666].
  • Hardcoded modules in the %files [bnc#444878].
  • Fixed the IfModule directive around SSLSessionCache [bnc#911159].
  • allow only TCP ports in Yast2 firewall files [bnc#931002]
  • fixed a regression when some LDAP searches or comparisons might be done with the wrong credentials when a backend connection is reused [bnc#930228]
  • Fixed split-logfile2 script [bnc#869790]
  • remove the changed MODULE_MAGIC_NUMBER_MINOR from which confuses modules the way that they expect functionality that our apache does not provide [bnc#915666]
  • gensslcert: CN now defaults to hostname -f [bnc#949766], fix help [bnc#949771]

Список пакетов

SUSE Enterprise Storage 1.0
apache2-mod_fastcgi-2.4.7-3.4.1
SUSE Linux Enterprise Server 12
apache2-2.4.10-14.10.1
apache2-doc-2.4.10-14.10.1
apache2-example-pages-2.4.10-14.10.1
apache2-mod_auth_kerb-5.4-2.4.1
apache2-mod_jk-1.2.40-2.6.1
apache2-mod_security2-2.8.0-3.4.1
apache2-prefork-2.4.10-14.10.1
apache2-utils-2.4.10-14.10.1
apache2-worker-2.4.10-14.10.1
SUSE Linux Enterprise Server for SAP Applications 12
apache2-2.4.10-14.10.1
apache2-doc-2.4.10-14.10.1
apache2-example-pages-2.4.10-14.10.1
apache2-mod_auth_kerb-5.4-2.4.1
apache2-mod_jk-1.2.40-2.6.1
apache2-mod_security2-2.8.0-3.4.1
apache2-prefork-2.4.10-14.10.1
apache2-utils-2.4.10-14.10.1
apache2-worker-2.4.10-14.10.1
SUSE Linux Enterprise Software Development Kit 12
apache2-devel-2.4.10-14.10.1

Описание

Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.


Затронутые продукты
SUSE Enterprise Storage 1.0:apache2-mod_fastcgi-2.4.7-3.4.1
SUSE Linux Enterprise Server 12:apache2-2.4.10-14.10.1
SUSE Linux Enterprise Server 12:apache2-doc-2.4.10-14.10.1
SUSE Linux Enterprise Server 12:apache2-example-pages-2.4.10-14.10.1

Ссылки

Описание

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.


Затронутые продукты
SUSE Enterprise Storage 1.0:apache2-mod_fastcgi-2.4.7-3.4.1
SUSE Linux Enterprise Server 12:apache2-2.4.10-14.10.1
SUSE Linux Enterprise Server 12:apache2-doc-2.4.10-14.10.1
SUSE Linux Enterprise Server 12:apache2-example-pages-2.4.10-14.10.1

Ссылки

Описание

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.


Затронутые продукты
SUSE Enterprise Storage 1.0:apache2-mod_fastcgi-2.4.7-3.4.1
SUSE Linux Enterprise Server 12:apache2-2.4.10-14.10.1
SUSE Linux Enterprise Server 12:apache2-doc-2.4.10-14.10.1
SUSE Linux Enterprise Server 12:apache2-example-pages-2.4.10-14.10.1

Ссылки

Описание

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.


Затронутые продукты
SUSE Enterprise Storage 1.0:apache2-mod_fastcgi-2.4.7-3.4.1
SUSE Linux Enterprise Server 12:apache2-2.4.10-14.10.1
SUSE Linux Enterprise Server 12:apache2-doc-2.4.10-14.10.1
SUSE Linux Enterprise Server 12:apache2-example-pages-2.4.10-14.10.1

Ссылки
Уязвимость SUSE-SU-2015:1851-1